CVE-2023-6634: LearnPress <= 4.2.5.7 - Command Injection
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the getcontent function. This is due to the plugin making use of the calluserfunc function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6634?
CVE-2023-6634 is classified as a critical vulnerability due to its potential to enable unauthenticated command injection.
How do I fix CVE-2023-6634?
To fix CVE-2023-6634, update the LearnPress plugin to version 4.2.5.8 or later.
Who is affected by CVE-2023-6634?
All versions of the LearnPress plugin for WordPress up to and including 4.2.5.7 are affected by CVE-2023-6634.
What types of attacks can be executed through CVE-2023-6634?
CVE-2023-6634 allows attackers to execute arbitrary commands on servers running the vulnerable LearnPress plugin.
Is CVE-2023-6634 a widespread vulnerability?
Yes, CVE-2023-6634 is widespread as it affects all users of the LearnPress plugin below version 4.2.5.8.